循大道,至万里 – 汽车事业部已连续三年完成《汽车数据安全管理情况报告》报送。
For the third consecutive year, BBM has completed the Automotive Data Annual Report

2021年《汽车数据安全管理若干规定》首次提出处理汽车重要数据的数据处理者应当在每年十二月十五日前网信部门和有关部门报送年度汽车数据安全管理情况 (“汽车年报”)。三年间,监管部门不断修订完善汽车年报报送方式、申报模板及风险评估指南。在C/DSO-CN的评估及指导下,汽车事业部GB/DSO,DSP积极协调,业务部门即时整合信息,这跨部门间积极且高效的协作,使得博世已连续三年出色地完成汽车年报的报送工作。
汽车数据安全是国家高度重视的话题,汽车数据处理的合规将进一步助力产业发展,激发数据价值。

In 2021, the Vehicle Data Security Measures (“VDSM”) proposed for the first time that data processors handling important vehicle data should report their vehicle data security management annual report (“vehicle data annual report”) to the regional CAC and relevant competent authority by 15 December each year. During the past three years, the regulator has continuously revised and improved the annual report reporting methods, templates of required documents and risk assessment guidelines. Under the evaluation and guidance of C/DSO-CN, BBM’s DSO, DSP actively coordinated with the business department to consolidate the information instantly, and this cross-departmental active and efficient collaboration has enabled Bosch to complete the vehicle data annual report submission for three consecutive years.
Vehicle data security is a topic of great importance to the state, and the compliance of vehicle data processing will further help the development of the industry and stimulate the value of data.

 
CBDT -个人信息出境标准合同办法》正式实施
Measures for Security Assessment of Outbound Data Transfer was enacted on September 1, 2022.

2022年9月1日《数据出境安全评估办法》正式实施 。
023年6月1日《个人信息出境标准合同办法》正式实施。
China Study Project项目团队已经在2023年2月正式提交了博世中国招聘管理、员工管理、运营管理事项的数据出境安全评估申报材料。经过多轮与各地监管部门的直接沟通和资料补充后,近期正式获得了受理通知,相信很快我们就会得到最终的批复结果。
项目组将会结合批复结果、申报过程中的经验和对外部趋势的研判,对常见的数据跨境场景,从数据合规的角度,给出更明确的结论和建议。我们将及时告知大家最新的进展。
同时,我们想特别感谢博世中国各实体及事业部代表、C/LSR-CN 、C/CGA-CN在报告筹备阶段和递交阶段的大力支持。
各实体及事业部代表名单,见C/DSO-CN Docupedia

Measures for Security Assessment of Outbound Data Transfer was enacted on September 1, 2022. Measures for Standard Contract for Cross-border Transfer of Personal Information was enacted on June 1, 2023.
China Study Project project team officially submitted the Cross Boarder Data Transfer Self Assessment report covering recruiting management, human resource management, office IT operation to supervision authority. After multiple rounds of direct communication with regional supervision authorities as well as the submission of supplementary documentations, we have recently received a formal acceptance notice. We believe that the final review result will be granted in no days.
The project team will consolidate the final review results, experience in preparation and submission of our report and the prospection of trends together with external professional judgements, provide Bosch with more specific conclusions and recommendation for common cross-border data transfer scenarios from data compliance perspective. We will keep you updated.
In the meantime, we would like to express our special gratitude to the rGB representatives of various entities and business units of Bosch China, as well as C/LSR-CN and C/CGA-CN, for their strong supports during the preparation and submission of the report.
rGB representatives namelist please refer to C/DSO-CN docupedia

 
“三驾马车”齐头并进,数据合规如何在企业落地?
How can data compliance be implemented in enterprises according to the Chinese “Three-Pillar” Law?

随着个人信息保护法及数据安全发的正式生效,中国已形成以网络安全,数据安全,个人信息保护为基础的数据合规“三驾马车”框架。
近年来,随着配套法规、规范性文件和相关指引的制定和施行,数据合规领域监管日趋严格,监管力度不断加强。如何快速认知、识别数据安全风险和确保数据合规落地成了悬在企业头上的“达摩克利斯之剑”。
博世中国数据合规调研项目(China Study Project)自2022年初由博世董事会批准立项以来,经过与各事业部、各实体代表、项目组成员跨地区、跨领域的合作。截止当前,已完成了博世整体合规风险分析、数据安全治理平台搭建、基础数据处理活动梳理,数据跨境传输申报、信息系统等级保护测评,个人信息保护影响评估认证等一些列里程碑工作。目前,项目组正在汇总所有的成果和方法论,将三法的合规要点和要求、工具、流程、模板融合进博世中国数据合规的治理框架中。以制度为基石、技术为手段、人才为保障,促进数据合规工作在博世中国的落地,提升合规水平,保障业务的连续运行。
China Study Project的详细信息可访问C/DSO-CN Docupedia

Data compliance legislation framework of China has been established based on “Three-Pillar Law”: Cyber Security, Data Security, Personal Information Protection.
With the formulation and implementation of supplementary regulations, normative documents and guidelines, data compliance supervision has become increasingly strict and regulatory efforts have been continuously strengthened. How do enterprise able to quickly recognize, identify data security risks, and ensure data compliance has become the sword of Damocles.
Since the approval of Bosch China Study Project by the GBM in early 2022, the team has accomplished a series of milestones including overall compliance risk analysis, preparation and releasing of data compliance management platform, registration of data processing activities, submission of cross-border data report, MLPS certificates of several systems, PIA certificates, etc together with the support from all Bosch China legal entities, rGB representatives and stakeholders from other regions.
Now, the team is consolidating all the requirements, methodologies, processes, tools and templates, integrating them into Bosch China data compliance governance framework. Aiming to facilitate the implementation of data compliance requirements within the organization, increase maturity level and safeguard the business continuity.
Visit C/DSO-CN Docupedia for more information of China Study Project.


 
MLPS

自项目启动以来,我们针对风险评估结果前8个高风险应用,陆续进行等保测评与持续改进,本轮测评中有3个三级系统,5个二级系统,在通过对系统的定级、备案、入场测评等一些列等保测评流程与系统整改后,目前以上系统都已通过等保测评要求,其中6个系统已出具测评报告,其余部分系统仍在持续改进中,通过强化网络防御、加强身份验证、完善安全审计和落实监控机制等安全措施,来进一步提高系统的安全可靠性。
通过本轮的等保测评,不仅是为了满足法规的要求,更是为了提高整体信息系统的安全性和稳定性。我们深入剖析了各个高风险应用的安全状况,全面了解了潜在的威胁和漏洞。同时也对标了等级保护测评要求与博世内部合规要求,有助于提前预见可能发生的安全威胁,使系统尽可能在满足外部合规要求的同时也满足内部要求,为用户数据和业务流程提供了强有力的保障。
关于等保的相关介绍,请访问C/DSO-CN Docupedia


Since the initiation of the project, we have conducted MLPS assessments and continuous improvements for the top 8 high-risk applications based on the results of risk assessments. In this round of assessments, there are 3 Level-3 systems and 5 Level-2 systems. After undergoing a series of MLPS processes such as system classification, filing, and entry assessment, along with subsequent system rectifications, all the mentioned systems have currently met the security requirements of the MLPS. Among them, 6 systems have already received assessment reports, while the remaining systems are still undergoing continuous improvements, through reinforcing network defenses, strengthening identity verification, enhancing security audit capabilities, and implementing monitoring mechanisms, we aim to further enhance the security and reliability of the systems.

The objective of this round of MLPS assessments is not only to meet regulatory requirements, but also to improve the overall security and stability of the information systems. We have conducted in-depth analyses of the security conditions of each high-risk application, gaining a comprehensive understanding of potential threats and vulnerabilities. Concurrently, we have aligned with both the MLPS requirements and internal compliance requirements at Bosch. This approach helps in anticipating potential security threats in advance, allowing the systems to comply with both external regulatory requirements and internal standards. This dual alignment provides robust protection for user data and business processes, ensuring a strong safeguard.

Visit C/DSO-CN Docupedia for more introduction of MLPS .


 
知其然,知其所以然 – 员工《个人信息收集声明》已更新发布
Know how and why – Employees‘ has been renewed
博世中国已更新并发布了《个人信息收集声明》, 向每一位员工披露公司处理您的个人信息的相关细节,以保护员工个人信息权益。
新版声明包含了更多细节信息,如:处理者的名称、处理个人信息的类别、目的、方式以及数据的境外接收方信息,等。
更多详情及FAQ,请访问C/DSO-CN Docupedia

Bosch China and its affiliates have updated and released the " Personal Information Collection Statement " to disclose to every Bosch employees the details of Bosch’s processing of your personal information so as to protect the your personal information rights and interests
The new version includes more specific information regarding, e.g. the name of data processors, type of personal information that are processed, purposes and manners of the processing as well as the overseas data recipients of your personal information, etc.
More details and FAQs, please visit C/DSO-CN Docupedia